Malware may implement features to make analysis and reverse engineering more difficult. These are known as anti-analysis or anti-reversing techniques.
Links to this note
- hypervisor enumeration
- anti-vm
- malware encrypted configuration
- malware vetting target hosts
- malware working hours
- nerbianratcovid19-proofpoint2022
- anti-debugger
- Main Index
- defendingagainstmaliciousshims-pierce2015
- knockknock-osxreverser2021
- homoglyph obfuscation
- process masquerading
- rootkits hiding CPU usage
- Skidmap malware
- most observed sshd backdoors shared the same rough feature set
- cesare1999
- Payload Encryption
- Azazel rootkit
- Compiler Options - Anti-Reversing
- crypter
- dynamic obfuscation
- function name randomization
- hidden files and directories
- honeypot detection
- IP Address Obfuscation
- IPfuscation
- Main Index - A
- malware blending in with the system
- Manual Analysis
- matryoshka obfuscation
- MemFiles
- stack strings
- string encryption
- string hashing
- string obfuscation
- timestomping
- unset HISTFILE
- userland exec
- Virtual Machine Detection